Vulnerability record · CVE-2021-22005 · published 23 September 2021
CVE-2021-22005: VMware vCenter Server Analytics arbitrary file upload to RCE
Vmware · Cloud Foundation
The Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-22), allowing code execution on the server. Because the service is reachable over the network and no credentials or user interaction are required, this is a high-value target for initial access into virtualized environments.
Description
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network code execution on a core virtualization management platform, with KEV listing, ransomware use and near-maximum EPSS.
What it is
The Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-22), allowing code execution on the server. Because the service is reachable over the network and no credentials or user interaction are required, this is a high-value target for initial access into virtualized environments.
Impact
An unauthenticated network attacker can upload a crafted file and execute code on the vCenter Server host, gaining control of the platform that manages ESXi hosts and virtual machines.
Attack surface
Reachable over the network on port 443 of the vCenter Server; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed to attempt exploitation.
Exploitation
Listed in CISA KEV with a due date of 2021-11-17 and flagged for known ransomware campaign use, and EPSS is effectively 1.0 (99.999% 30-day probability); public exploit code is referenced by Packet Storm.
What to do
- Apply the vendor updates in VMware advisory VMSA-2021-0020 immediately; this is the required KEV action.
- If patching cannot be completed at once, restrict network access to port 443 on vCenter Server to trusted management networks only.
- Isolate vCenter management interfaces from general user and internet-facing networks.
- After patching, rotate credentials and review vCenter and ESXi accounts for unauthorized changes.
- Monitor vendor guidance for any additional workaround steps specific to the Analytics service.
Detection
- Review vCenter and Analytics service logs for unexpected file uploads or writes outside expected directories.
- Hunt for new or modified files in vCenter Analytics and web-accessible paths, especially files with unusual extensions or content.
- Monitor for unexpected child processes spawned by the vCenter Analytics service or web server.
- Alert on anomalous outbound connections from vCenter Server hosts to unfamiliar destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22005 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164439/VMware-vCenter-Server-Analytics-CEIP-Service-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | PatchVendor Advisory |
| http://packetstormsecurity.com/files/164439/VMware-vCenter-Server-Analytics-CEIP-Service-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22005 | US Government Resource |
Track CVE-2021-22005 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.